CYBER-0 added a tooling list
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
---
|
||||
title: list of testing types and tools
|
||||
state: draft
|
||||
date: 20260921
|
||||
---
|
||||
|
||||
## List of tools
|
||||
|
||||
|#|Testing Lane|Current State|Cadence Signal|Evidence / Owner Confidence|Purpose / Descriptor|Automation Likelihood|Rationale|Typical Pipeline Stage|
|
||||
|---|---|---|---|---|---|---|---|---|
|
||||
|1|SAST|Strong|Every code change|Pipeline results, supported|Identifies coding flaws, insecure patterns and implementation weaknesses in source code.|**Very High**|Mature tools with deterministic execution and immediate developer feedback.|Commit / Pull Request|
|
||||
|2|SCA / SBOM|Strong|Build + regular monitoring|SBOM, vulnerability records, supported|Detects vulnerable dependencies, license issues and component supply-chain risks.|**Very High**|Fully automatable through build integration and continuous monitoring.|Build + Continuous Monitoring|
|
||||
|3|Component / API Testing|Partial|After successful Stage 1|Coverage and test results, partial|Verifies service contracts, interfaces, business logic and API behavior.|**High**|Easily automated when interfaces are stable and testable.|CI / Integration|
|
||||
|4|IAST|Decision Needed|Not defined|Scope, tool and owner to confirm|Runtime analysis during test execution to identify security weaknesses with application context.|**High**|Generally automated once tooling and deployment model are established.|Integration / Pre-production|
|
||||
|5|DAST / Runtime Scan (ASVS 5)|Gap / Partial|Nightly / Release Target|Scan report, owner to confirm|Detects externally observable vulnerabilities in deployed applications.|**High**|Automated scanning is straightforward, but tuning and triage require human involvement.|Nightly / Release Validation|
|
||||
|6|DAST - Destructive Pen Test|Gap|Release / Major Change|Security assessment report|Validates resilience against aggressive attack scenarios that may disrupt service.|**Low**|Requires controlled environments, expert judgment and risk management.|Pre-release / Special Campaign|
|
||||
|7|Performance / Load / Fuzz Testing|Gap|Nightly + Daily Target|Trend analysis, thresholds, owner to confirm|Measures scalability, robustness and resistance to malformed inputs.|**High**|Modern load and fuzz frameworks automate execution and trending effectively.|Nightly / Continuous Validation|
|
||||
|8|Integration / Regression Testing|Gap / Partial|Daily + SIT|Test suite results, shared ownership|Verifies system interactions and prevents previously corrected defects from reappearing.|**Very High**|Core CI/CD practice with strong automation support.|CI / SIT|
|
||||
|9|Operational Vulnerability Scan|Gap / Partial|Regular Operations|Rapid7 / OBOM Scanning?|Assesses deployed environments, hosts, middleware and infrastructure exposure.|**High**|Scanning can be fully automated, remediation remains operationally driven.|Operational / Continuous Monitoring|
|
||||
|10|FAT / SAT|Partial|Per Project / On-site|Project package, scope to confirm|Confirms contractual and operational acceptance criteria before handover.|**Low-Medium**|Some execution can be automated, but customer validation is largely manual.|Project Gate|
|
||||
|11|Hardening Benchmark|Partial|Release (& Operational?)|Benchmark reports|Validates compliance with secure configuration standards and baselines.|**High**|CIS, DISA STIG and platform baseline checks are highly automatable.|Release + Operations|
|
||||
Reference in New Issue
Block a user